Choose your language
Digital forensics and Cybersecurity Course
Over 400,000 professionals on the platform
Exclusive for businesses

Digital forensics and Cybersecurity Course

Master the technical and legal skills that define professional digital forensics and cybersecurity investigation. This course takes you from core evidence principles to advanced memory, network, and cloud forensics. You will graduate ready to investigate real incidents, testify as an expert, and protect organizations from evolving threats.

Dedika for students

What your team will master:

You will build a complete forensic skill set covering evidence acquisition, disk and file system analysis, memory forensics, and network traffic investigation. You will learn how to set up a compliant forensic lab, maintain chain of custody, and produce court-admissible evidence. The course covers incident response workflows, threat hunting, malware analysis, and cloud forensics. You will also study mobile and IoT device investigation, threat intelligence integration, and penetration testing fundamentals. By the end, you will know how to write professional forensic reports and perform effectively as an expert witness.

How your team learns in practice Digital forensics and Cybersecurity Course

How your team practices Digital forensics and Cybersecurity Course

Professionals from these companies study at Dedika

ActemiumFR
Nunner LogisticsNL
GT Constructora GeotécnicaCR
Sydel StarBR
Metrô de São PauloBR
Aguas AndinasCL
DSMIN
MeridianbetRS
CDHCN

Course Content

8 Chapters • 40 LessonsDuration between 4 and 360 hours (you decide)

Chapter 1See details

Foundations of Digital Forensics

  • Lesson 1 • Legal and Ethical Foundations

    Covers admissibility standards, chain of custody, and investigator ethics. Connects legal requirements to every subsequent technical procedure.

  • Lesson 2 • Types of Digital Evidence

    Catalogs volatile, non-volatile, and network-based evidence categories. Prepares students to recognize evidence types before learning acquisition techniques.

  • Lesson 3 • The Forensic Investigation Process

    Presents the standard phases: identification, preservation, collection, analysis, and reporting. Students map each phase to real-world investigative tasks.

  • Lesson 4 • Introduction to Digital Forensics

    Defines digital forensics, its scope, and its role in legal and corporate investigations. Grounds students in the discipline before any technical content.

  • Lesson 5 • Forensic Lab Setup and Standards

    Describes hardware, software, and procedural requirements for a compliant forensic lab. Students understand the environment in which all subsequent work occurs.

Chapter 2See details

Cybersecurity Fundamentals for Investigators

  • Lesson 1 • Security Controls and Their Forensic Relevance

    Reviews firewalls, IDS/IPS, SIEM, and access controls as sources of forensic artifacts. Students learn to query security tools for evidence.

  • Lesson 2 • Cryptography Essentials

    Introduces hashing, symmetric and asymmetric encryption, and PKI as they apply to evidence integrity and encrypted data challenges.

  • Lesson 3 • Networking Concepts for Forensics

    Covers TCP/IP, DNS, DHCP, and packet structure as they relate to evidence interpretation. Provides the network literacy required for later traffic analysis chapters.

  • Lesson 4 • Operating System Internals

    Examines Windows, Linux, and macOS artifacts relevant to forensic analysis. Students learn where the OS stores evidence before performing disk analysis.

  • Lesson 5 • Threat Actors and Attack Taxonomy

    Classifies threat actors, motives, and common attack categories to frame investigative hypotheses. Directly supports the incident response chapters that follow.

Chapter 3See details

Evidence Acquisition and Preservation

  • Lesson 1 • Hashing and Evidence Integrity

    Demonstrates MD5, SHA-1, and SHA-256 verification workflows to prove evidence has not been altered. Ties integrity verification to chain of custody documentation.

  • Lesson 2 • Live System and Volatile Data Capture

    Addresses RAM capture, running process lists, and network state collection on live systems. Prepares students for memory forensics in the next chapter.

  • Lesson 3 • Disk Imaging Principles and Tools

    Covers bit-for-bit imaging, image formats, and leading acquisition tools. Establishes the technical baseline for all subsequent disk analysis work.

  • Lesson 4 • Mobile Device Acquisition

    Covers logical, file system, and physical extraction methods for smartphones and tablets. Addresses the unique challenges of mobile evidence preservation.

  • Lesson 5 • Network Traffic Capture

    Teaches packet capture placement, tool configuration, and evidence preservation for network data. Connects to network forensics analysis covered later.

Chapter 4See details

Disk and File System Forensics

  • Lesson 1 • Partition and Volume Analysis

    Analyzes MBR, GPT, and volume shadow copies to find hidden or deleted partitions. Expands the scope of disk examination beyond the primary partition.

  • Lesson 2 • File Recovery and Data Carving

    Covers deleted file recovery, slack space analysis, and signature-based carving. Students apply these techniques to recover evidence from unallocated space.

  • Lesson 3 • File System Structures

    Examines FAT, NTFS, ext4, and APFS structures to locate evidence at the sector level. Understanding structure is prerequisite to recovery and carving techniques.

  • Lesson 4 • Metadata and Timestamp Analysis

    Extracts and interprets file metadata, EXIF data, and MACB timestamps to build event timelines. Directly feeds the timeline analysis section of this chapter.

  • Lesson 5 • Timeline Construction from Disk Artifacts

    Aggregates timestamps from multiple disk sources into a unified event timeline. Students produce a timeline that supports investigative conclusions.

Chapter 5See details

Memory and Malware Forensics

  • Lesson 1 • Process and DLL Analysis

    Identifies malicious processes, injected DLLs, and hollowed processes within memory images. Core technique for detecting fileless and in-memory malware.

  • Lesson 2 • Malware Identification and Classification

    Applies static and behavioral indicators to classify malware families found in memory. Prepares students for deeper malware analysis in the next section.

  • Lesson 3 • Network Artifacts in Memory

    Extracts active connections, listening ports, and socket structures from RAM. Connects memory findings to network forensics evidence for corroboration.

  • Lesson 4 • Memory Structure and Acquisition Review

    Reviews RAM layout, virtual address spaces, and acquisition methods before analysis begins. Ensures students can work with memory images from the previous chapter.

  • Lesson 5 • Malware Analysis Techniques

    Introduces static disassembly, dynamic sandbox execution, and code unpacking for malware samples. Students produce an analysis report suitable for incident response.

Chapter 6See details

Network Forensics and Log Analysis

  • Lesson 1 • Packet Capture Analysis

    Teaches deep packet inspection, stream reassembly, and protocol decoding using capture files. Builds on acquisition skills to produce actionable network evidence.

  • Lesson 2 • Flow Data and NetFlow Analysis

    Uses flow records to identify anomalous traffic patterns and data exfiltration without full packet data. Complements full packet analysis for high-volume environments.

  • Lesson 3 • Intrusion Detection and Attribution

    Applies network evidence to confirm intrusion, identify lateral movement, and support attribution. Culminates network forensics skills into a complete investigation narrative.

  • Lesson 4 • System and Security Log Correlation

    Correlates Windows event logs, syslog, and firewall logs to build a cross-source attack timeline. Integrates with SIEM concepts introduced in Chapter 2.

  • Lesson 5 • Web and Application Log Analysis

    Parses web server, application, and proxy logs to reconstruct attacker web activity. Directly supports investigation of web-based attack vectors.

Chapter 7See details

Incident Response and Threat Hunting

  • Lesson 1 • Incident Response Lifecycle

    Maps the preparation, detection, containment, eradication, recovery, and lessons-learned phases to forensic tasks. Provides the operational framework for this chapter.

  • Lesson 2 • Post-Incident Analysis and Lessons Learned

    Structures root cause analysis, gap identification, and control improvement after an incident. Closes the IR lifecycle and feeds improvements back into security posture.

  • Lesson 3 • Containment and Eradication Strategies

    Examines network isolation, account disabling, and malware removal while preserving evidence. Balances operational recovery needs with forensic integrity requirements.

  • Lesson 4 • Triage and Rapid Assessment

    Covers rapid host triage, artifact prioritization, and scope determination under time pressure. Enables investigators to make fast, evidence-based containment decisions.

  • Lesson 5 • Threat Hunting Fundamentals

    Introduces hypothesis-driven hunting using TTPs, threat intelligence, and behavioral analytics. Extends reactive IR skills into proactive detection capability.

Chapter 8See details

Forensic Reporting and Expert Testimony

  • Lesson 1 • Writing for Technical and Legal Audiences

    Adapts forensic findings for attorneys, executives, and technical peers without sacrificing accuracy. Develops the communication versatility investigators need in practice.

  • Lesson 2 • Expert Witness Preparation

    Prepares students for deposition, direct examination, and cross-examination as a forensic expert. Addresses the unique pressures of testifying in adversarial proceedings.

  • Lesson 3 • Case File Management and Archiving

    Establishes procedures for organizing, securing, and archiving complete case files for future reference. Ensures long-term defensibility of investigative work product.

  • Lesson 4 • Forensic Report Structure and Standards

    Defines required report sections, objectivity standards, and documentation best practices. Establishes the reporting framework used throughout the final project.

  • Lesson 5 • Evidence Presentation and Visualization

    Covers timeline charts, network diagrams, and artifact maps that make complex evidence accessible. Directly supports both written reports and courtroom presentations.

Certification

Your valid completion certificate

This course is for you:

  • IT Administrator: wants to formalize incident handling skills with investigative rigor.

  • Career Changer: brings analytical thinking and is ready to enter cybersecurity professionally.

  • Security Analyst: needs deeper forensic methodology to support escalated threat investigations.

  • Law Enforcement Officer: handles digital evidence and wants stronger technical examination skills.

  • Compliance Professional: must understand how digital investigations protect organizational liability.

  • Computer Science Graduate: seeks a specialized, career-defining edge in the security job market.

Related Courses

FAQ

Who is Dedika?

Is the certificate valid in Canada?

Are the courses free?

What is the course workload?

What are the courses like?

How do the courses work?

What is the duration of the courses?

What is the cost or price of the courses?

What is an EAD or online course and how does it work?

PDF Course